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In the Specification: 

Please replace paragraphs 0034 and 0035 as follows: 

[0034] Referring now to Figure 4, the negotiation authentication scheme described 

above in step 90 is further described in step 102. The client privilege server proxy proposes 
one security mechanism or an ordered list of security mechanisms to the privilege server 26. A 
negotiation token may be used to establish the authentication mechanism context. In step 104, 
if the privilege server authentication model decoding modules are not present within the client 
machine, the user 1 2 may try to download the module from a specific URL The privilege server 
accepts or rejects step 104. It the token is not accepted in step 106, step 102 is re-executed. If 
the token is accepted in step 106, the token is stored instep 108 . Once a mechanism has been 
selected, tokens specific to the selected mechanism are carried with a security token. The 
token may, for example, include various information such as a time stamp In step 110. Time 
stamping a token may include providing a start time, a stop time, and a duration length of the 
valid token, 

[0035] Referring now to Figures 1 , 2 and 5, once authentication has taken place as 
illustrated in Figure 3, user access to a particular service 30 is provided. As mentioned in 
Figure 3, the user is provided a session key and sequence number from the privilege server. 
User 12 presents the ticket and sequence number encrypted in step 112 with the session key to 
a service 30 such as data server 32 through web adapter 18. 

Please replace paragraph 0038 as follows: 

[0038] Referring now to Figures 1, 2, and 6, various administration functions may also 

be performed by system 10, One such function is registering a user. In step 24, a request for 
user registration is received by privilege server 26 In step 122 . The user sends its user ID and 
required information based upon the underlying authentication scheme to web adapter 18. Web 
adapter 1 8 provides the information to privilege server through head end server 20. 

Please replace paragraph 0042 as follows: 

[0042] Referring now to Figures 1, 2, and 8, the administrative functions may also 

include logging out of the system, The privilege server proxy 14 requests a sequence number 
in step 136 and session key from privilege server 26 through head end server 20 and web 
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adapter 18 by sending the head end server access request token encrypted with a ticket and 
the user ID. 
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